Dotfuscator protects applications through obfuscation, tamper detection, and other protection techniques. These safeguards help protect your intellectual property and revenue by making software more resistant to reverse engineering, modification, and other threats.
Malware can use similar obfuscation and protection techniques to conceal malicious behavior. As a result, antivirus tools might incorrectly identify a legitimate application or library protected by Dotfuscator as malicious. This is known as a false positive.
Investigate a Potential False Positive
If an antivirus tool flags your protected application:
- Build and scan the application without Dotfuscator protection enabled.
- Rebuild the application with Dotfuscator protection enabled, and then scan it again.
- Compare the scan results to determine whether the detection occurs only in the protected build.
- If the protected build continues to trigger the detection, report the false positive to the antivirus provider.
Following these steps helps determine whether the detection is associated with the protections applied by Dotfuscator. Reporting the result also allows the antivirus provider to review the detection and, when appropriate, update its detection algorithms.
Report a False Positive
The following table provides submission resources for several antivirus providers:
| Company | Where to report? |
|---|---|
| Avira | https://www.avira.com/en/analysis/submit |
| Kaspersky | https://support.kaspersky.com/common/error/other/15332 |
| McAfee | https://www.mcafee.com/en-us/consumer-support/dispute-detection-allowlisting.html |
| Microsoft | https://www.microsoft.com/en-us/wdsi/filesubmission |
| Symantec | https://symsubmit.symantec.com/ |
| VirusTotal | https://docs.virustotal.com/docs/false-positive-contacts |
Contact PreEmptive Support
If the antivirus provider rejects your false-positive submission, contact the PreEmptive Support team and include the antivirus tool’s analysis and detection results.
Although PreEmptive cannot guarantee that Dotfuscator-protected applications will never trigger antivirus detections, the Support team can review the findings and identify potential improvements to the product.